CVE Database
/

CVE-2025-66257

Back to search

CVE-2025-66257

Published: Nov 26, 2025

Modified: Nov 26, 2025

PUBLISHED

Description

Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletepatch parameter allows unauthenticated deletion of arbitrary files. The `deletepatch` parameter in `patch_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/patch/` directory without sanitization or access control checks.

VendorProductVersions

DB Electronica Telecomunicazioni S.p.A.

Mozart FM Transmitter

affected
30
affected
50
affected
100
affected
300
affected
500

+6 more versions

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now